logo

MongoDB warns admins to patch severe vulnerability immediately

ID: 338eb8c3-cb65-5ab9-8797-c926940f79b8

STIX ID: report--338eb8c3-cb65-5ab9-8797-c926940f79b8

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

MongoDB warned administrators of CVE-2025-14847, a high-severity memory-read vulnerability in the Server's zlib implementation that may allow unauthenticated remote attackers to obtain uninitialized heap memory and — according to its CWE-130 classification — could in some cases enable arbitrary code execution; affected MongoDB and MongoDB Server versions span many widely used releases, and operators are urged to upgrade to specific fixed versions immediately or disable zlib compression as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.